Last reviewed · 9 Aug 2026
Privacy, enquiries, and assessment terms.
This page explains how the current site behaves and the minimum boundaries for enquiries and authorized assessment work. It is not a substitute for a signed service agreement, privacy review, or Rules of Engagement.
Current site behavior
Privacy and external channels
This site has no accounts, first-party forms, payments, newsletter, or analytics cookies. Hosting infrastructure may process ordinary request logs for site delivery, abuse prevention, and security.
The contact page can open the visitor's default mail app, open a prepared message in Gmail or Outlook, or copy a brief for another provider. The website does not receive or store the message. Email is processed by the sender's selected provider and the CyberKareem business-mail provider. LinkedIn, Discord, GitHub, X, credential providers, and lab platforms are external services with their own privacy terms. The public Discord invite is for community discussion, not confidential scoping or disclosure.
The site uses one fixed visual appearance and does not store a color-theme preference in the visitor's browser.
Commercial enquiries
An enquiry is not an engagement.
An initial assessment enquiry may identify the organization, requester role, service category, high-level asset type, desired outcome, timing, and authorization owner. Do not include target URLs, IP addresses, credentials, source code, vulnerability evidence, personal data, or confidential architecture.
No assessment starts until fit, professional obligations, contracting authority, written authorization, scope, and Rules of Engagement are confirmed. A separate signed agreement controls the actual engagement.
Responsible disclosure
Coordinate before sharing sensitive evidence.
The published info@cyberkareem.com domain mailbox supports identity establishment and a request for a private channel. Ordinary email is not a confidential vulnerability-report intake. Do not send exploit code, credentials, personal data, or unpatched technical detail until a suitable private channel is confirmed.
The published security.txt record provides the current disclosure contact and policy route. It does not authorize testing or make ordinary email a secure evidence channel.
The disclosure guidance supports coordination concerning published CyberKareem research and legitimate inbound vulnerability contact; it does not create a bug-bounty program or authorize testing.
Assessment rules
Authorization comes first.
- The legal owner and authorized client representative must be identified.
- Assets, environments, accounts, dates, third parties, and permitted techniques must be written into scope.
- Smart-contract scope must identify the exact source snapshot, compiler and toolchain, intended chain, deployment state, external dependencies, privileged roles, and agreed test environment.
- Emergency contacts, stop conditions, evidence handling, and reporting recipients must be agreed.
- Social engineering, denial of service, persistence, destructive testing, and real-user-data access remain excluded unless explicitly and safely authorized.
- Cloud, hosting, wireless, and other third-party provider requirements remain the client’s responsibility to confirm.
- A Solidity/EVM readiness review is point-in-time and bounded. It is not formal verification, non-EVM review, exhaustive economic assurance, or a substitute for multiple independent reviews on critical or high-value protocols.
Independent engagements are accepted only where professional obligations, conflicts, legal contracting requirements, and any required third-party approvals permit. No current or former employer is represented as endorsing this independent site.
Public portfolio standards
What appears in this portfolio.
- Research claims link to a primary advisory, vendor record, patch, or CyberKareem-authored case study with reproducible evidence.
- Client and employer work remains generalized unless publication is explicitly cleared.
- Dynamic ranks and totals are dated or linked instead of presented as permanent facts.
- Tools are described by demonstrated behavior and limits, not broad assurance labels.
This standard applies to the About, Projects, Research, and Writing sections. A public portfolio should make claims checkable without publishing client data, private research, or employer-sensitive detail.